Let your team reach Rembrandt through the identity provider you already run, so access follows the accounts your IT department manages.
What is supported
OpenID Connect (OIDC) against your provider, configured per organization:
-
Okta
-
Microsoft Entra ID
-
Google Workspace
-
Any OIDC-compliant provider
You supply the email domain your people sign in with, plus the client credentials from your provider. Sign-in is then routed to your identity provider for everyone on that domain.
SAML and SCIM provisioning are on the roadmap. Until SCIM ships, membership is managed in Rembrandt under Settings → Organization → Members, and removing someone in your identity provider stops them signing in.
Availability
Single Sign-On is enabled per organization and is switched off by default. If there is no Single Sign-On entry under Settings → Organization, it is not enabled for yours yet.
Talk to your account team. Setting it up is done with you rather than self-serve, because the connection has to be validated against your provider before your team depends on it for access.
Documentation
Full setup documentation is published alongside enablement, and your account team walks your IT administrator through the provider configuration.
Without SSO
Until Single Sign-On is in place, your team signs in with email and password or with Google. An Owner or Admin can require two-factor authentication for everyone who uses a password, under Settings → Organization → Security. See Organization.
Need help
-
Organization: members, roles, and security
- Troubleshooting
-
support@rembrandtagents.com